Orbital Transports

    Research note · Semiconductor provenance

    The Rule That Decides Whether You Can Sell Into Federal Missions

    This law doesn't ask if your parts are clean. It asks if you can prove you checked, and the deadline is closer than it looks.

    In December 2022, Congress passed a provision that quietly changed what 'knowing your supply chain' means for anyone selling into a federal mission. Three years later, the rule that enforces it is moving through its final stages, and the deadline sits closer than most SmallSat teams realize. This Research Note lays out exactly what Section 5949 requires, why it's harder to satisfy than it looks, and what happens if you get it wrong.

    Find Out About Provenance Tracker

    Preview spots are limited.

    Schedule A Preview

    The Law That Matters For Your Mission

    On December 23, 2022, President Biden signed the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 into law.

    It's over 4,400 pages and covers almost everything the Department of Defense does in a given year.

    Buried inside it, a few paragraphs with nothing to do with ships or personnel: Section 5949.

    Section 5949 and You

    Section 5949 bans federal agencies from procuring anything that contains a semiconductor from a specific set of restricted manufacturers.

    To comply, a contractor has to conduct a genuine inquiry into its own supply chain, deep enough to actually answer the question, and certify the result.

    Why This Impacts The SmallSat Industry

    If your mission touches, or is ever likely to touch, a federal agency, directly or through a prime, this impacts your bill of materials, whether or not anyone's asked you about it yet.

    The restriction names three companies specifically: Semiconductor Manufacturing International Corporation (SMIC), ChangXin Memory Technologies (CXMT), and Yangtze Memory Technologies Corporation (YMTC), along with their subsidiaries and affiliates.

    All three were already under separate export-control scrutiny before this statute, part of a broader U.S. policy response to state-subsidized competition and supply chain dependency in critical semiconductor manufacturing.

    The Detail That Catches You Out

    This is the detail that catches most technical teams off guard: the restriction attaches to the semiconductor die itself. Not the part number. Not the distributor. Not the country the box shipped from.

    Your datasheet tells you electrical characteristics. It almost never tells you where the die was actually fabricated, because packaging, testing, and fabrication are frequently three different companies in three different countries.

    And getting this wrong isn't a paperwork problem.

    Every certification you submit is a legal claim to the federal government. A false one carries treble damages, a civil penalty currently set at $14,308 to $28,619 per instance, and potential debarment from future federal contracting.

    There's a real safe harbor here too: disclose a gap you find yourself, and you're protected from most of that exposure. This catches people who never looked, not people who looked and found something imperfect.

    The Bigger Implication

    In practice, this cuts wider than it first looks.

    If you can't identify and certify where your parts come from, you're locked out of selling to anyone who might eventually sell into a federal agency, not just the government itself.

    And it doesn't stop at the finished part. It reaches into the components, and potentially the materials, that go into building it.

    What Happened in February 2026

    For three years, Section 5949 sat as a statute with no enforcement mechanism, real, but distant.

    That changed on February 17, 2026, when the FAR Council, the body that writes the actual procurement regulations, published its proposed rule implementing it.

    That's the document that turns this from a law into something a contracting officer actually checks.

    The New Deadline

    The statute set enforcement at December 23, 2027, sixty months after it was signed into law on December 23, 2022.

    As of today, that's roughly 14 months away, inside the design, sourcing, and qualification cycle of a mission that may already be on your roadmap.

    A part sourced today, for a spacecraft that launches in 2028 or later, has its compliance status effectively locked in at the moment of sourcing.

    There's no fixing it retroactively once it's integrated and flying.

    Why This Is a Challenge

    Most bills of materials were never built to answer where a die was actually fabricated, because until now, nobody needed them to.

    You're not buying from one supplier, you're buying through a chain, your direct vendor, their distributor, sometimes a trading house, eventually a fabrication facility you've likely never heard of and have no direct relationship with. Most small SmallSat teams have visibility into the first link or two of that chain, and nothing beyond it.

    It doesn't stay still, either. Suppliers switch fabs. They re-source under shortage pressure. They get acquired, and their sourcing changes with them, often without telling you. A supply chain map from eighteen months ago tells you almost nothing reliable about what's actually in your BOM today.

    Your Options

    Realistically, three paths from here, and only one of them actually resolves anything.

    Do nothing. Not a strategy, a bet that nobody checks before your next bid. That bet gets worse every month, not better.

    Build the capability internally. The honest, defensible option, and expensive in a way that doesn't show up until you're already inside it. Someone has to trace your BOM through every tier, interpret entity lists correctly, chase documentation from vendors with no particular reason to hand it over, and keep the record current. That's not a project with an end date, it's a standing function.

    Have this done by people who already do it. The work doesn't disappear, tracing, documenting, maintaining, someone still does all of it. It just stops being something your own engineering team absorbs on top of everything else.

    This Goes Wider Than Compliance

    Even without Section 5949, knowing where your components actually come from is becoming standard practice, not because a statute demands it, but because it's simply better engineering.

    When a quality problem or shortage hits, companies that know their full supply chain can react immediately. The ones that don't start investigating from zero, usually at the worst possible moment, mid-build and under schedule pressure.

    Section 5949 is the reason this is urgent right now. It won't be the last reason it matters.

    This Isn't a One-Off Task

    A provenance check done once and filed away goes out of date the moment any of that changes upstream. This has to be something you maintain continuously, not something you complete and move past.

    We're Launching Provenance Tracker

    That's why we're launching Provenance Tracker.

    It maps your component sourcing tier by tier, documents what's confirmed and what isn't with a stated confidence level for each finding, and keeps that record current as your suppliers and their own sourcing change, instead of going stale the day after it's produced.

    You get a real answer to where your components come from today, a defensible record ready to support your own certification, and a system that stays accurate instead of needing to be redone from scratch every time something upstream changes.

    Get an Early Look at Provenance Tracker

    Book a walkthrough of Provenance Tracker, to see how prepared you are for the new legal requirements.

    Schedule A Preview